Junglewise Threat Intelligence

CVE-2026-60521: Oracle Advanced Pricing unauthorized data access in Price List

CVE-2026-60521 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Price List component of Oracle Advanced Pricing, a tool used by businesses to manage complex pricing logic and customer agreements. An unauthenticated attacker could remotely access the system over the network to view, modify, or delete sensitive pricing data. This could lead to unauthorized changes in product pricing, loss of data integrity, or exposure of proprietary pricing strategies.

Technical details

This vulnerability affects the Price List component of Oracle Advanced Pricing within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation grants unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The vulnerability has a CVSS 3.1 base score of 6.5, reflecting impacts on confidentiality and integrity without affecting availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Advanced Pricing (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle released the Critical Patch Update (CPU) containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60521 was published to the NVD.

References